Escaping by default -- possible without editing the lib?
Tim McCormack <[email protected]>
| Newsgroups | gmane.comp.web.freemarker.user |
|---|---|
| Message-ID | <[email protected]> |
I'm looking into a number of HTML templating libraries, and so far they all have
the downside of providing no way to escape all data for HTML by *default*.
In the case of FreeMarker, I'm aware of the <#escape as> directive, but the
developer has to remember to include that on every page! This makes me a bit
uneasy -- just like having to remember to put charset=UTF-8 on every page
instead of instructing the server to always add that header.
Other than hacking on the jar, is there a way to ensure that the default is to
escape all ${data} as HTML?
- Tim McCormack
------------------------------------------------------------------------------
ThinkGeek and WIRED's GeekDad team up for the Ultimate
GeekDad Father's Day Giveaway. ONE MASSIVE PRIZE to the
lucky parental unit. See the prize list and enter to win:
http://p.sf.net/sfu/thinkgeek-promo